Let's get the uncomfortable bit out of the way first. Most organisations are still hiring cybersecurity teams based on 2023's threat landscape and 2024's budget constraints. I've spent the last three months reviewing security headcounts across financial services and critical infrastructure, and the disconnect between what firms think they need and what they actually need has never been wider.
After seven years in the SOC trenches and now working with hiring managers daily, I'm seeing patterns that should worry anyone responsible for security headcount planning. The rush to secure AI systems has left basic security functions understaffed, while over-investment in certain specialist roles has created expensive bottlenecks.
So what should your cyber team actually look like in August 2026? Here's my priority list, based on what's working for the organisations that are getting it right.
OT/ICS Security Specialists (Finally, Their Moment)
I've been banging this drum for ages, but the last eight months have made it undeniable: OT/ICS security specialists should be your top hiring priority if you have any industrial or infrastructure footprint whatsoever.
The Colonial Pipeline incident feels like ancient history now, but the sustained targeting of UK water utilities since March has been a wake-up call. Five separate intrusion attempts, all targeting legacy SCADA systems with virtually identical TTPs.
The skills gap is brutal. I recently had a client ready to offer £110K for someone with just three years of ICS security experience. They couldn't find a suitable candidate for six weeks.
Candidates with both IT and OT security backgrounds are unicorns. Look for people with control systems engineering backgrounds who've made the security pivot, rather than IT security specialists who've done a crash course in OT.
Beyond Tick Boxes: Diversity Recruitment Strategies That Actually Transform UK Workplaces
Master the Virtual Hot Seat: 7 Video Interview Techniques Recruiters Don't Tell You
How to Master 'Tell Me About Yourself' Interview Question: UK Expert Insights
Cloud Security Architects (But Not Just Any)
We all know cloud security has been important for ages. The difference in 2026? You need people who understand security across multi-cloud environments that include sovereign cloud deployments.
The UK Government Cloud Strategy finalised back in January has pushed numerous organisations toward hybrid deployments that span AWS, Azure, and UK sovereign clouds. Finding security architects who can design controls that work consistently across these environments is brutally difficult.
What's happening on the ground is telling. One bank I work with had to pull three engineers off project work to address gaps in their cloud security architecture. They're now offering £145K base for the right candidate with multi-cloud and sovereign cloud experience. That's £20K more than last year for essentially the same job title.
Don't be fooled by certifications alone. I've interviewed people with every AWS and Azure security cert imaginable who couldn't explain how to implement consistent identity controls across hybrid environments.
Supply Chain Security Leads
This role barely existed three years ago. Now it's critical.
The updates to NIS2 regulations have completely changed the game for UK organisations. The liability model means you're now accountable for security incidents that originate in your supply chain - even if you've done your due diligence.
What makes a good supply chain security lead? It's not just technical skills. You need someone who can:
- Build and enforce vendor security assessment processes
- Work with procurement and legal on contractual security requirements
- Design incident response protocols that include supplier coordination
- Communicate security requirements to business stakeholders who might not care
Salary ranges vary wildly, but expect to pay £85-110K in London, less elsewhere. The most effective hires I've placed in this role have come from GRC backgrounds but with solid technical foundations.
AI Security Specialists (But Be Selective)
Look, we all know AI security specialists are in demand. But the market is flooded with people who've rebranded themselves as "AI security experts" after taking a few courses.
What you actually need are security professionals who understand:
- Prompt injection mitigations beyond the basics
- Data poisoning detection and prevention
- Model security testing methodology
- Integration of AI security into existing security frameworks
Avoid candidates whose knowledge begins and ends with "I've read the OWASP AI Security Top 10." The best hires come from traditional application security backgrounds and have made a deliberate transition into AI security.
One of my clients just hired a brilliant AppSec specialist who'd spent six months researching and documenting model theft techniques. They beat out candidates with "AI Security" already in their job titles because they demonstrated actual practical knowledge.
Security Awareness Specialists (But Not As You Know Them)
Wait, what? Security awareness specialists as a top hiring priority? Am I serious?
Completely. But I'm not talking about the people who run phishing simulations and make posters about password hygiene.
The most effective security teams in 2026 have security culture specialists who:
- Design contextual security nudges integrated into workflows
- Measure and improve security behaviours using behavioural science
- Create targeted intervention programmes for high-risk groups
- Quantify the ROI of security behaviour change
This isn't the security awareness role of yesteryear. These specialists typically have backgrounds in psychology, behavioural economics, or user experience design combined with security knowledge.
Some of the most impressive security improvements I've seen recently came from teams who invested in this capability. One retailer reduced their phishing click rates by 62% through contextual interventions rather than punitive training.
The Roles You Can Deprioritise
I'll probably catch flak for this, but based on what I'm seeing across dozens of security teams, you can slow down hiring in these areas:
- Generic SOC Analysts (Tiers 1-2) - Automation and managed services have drastically reduced the need for junior SOC headcount
- Compliance Specialists - Important but outsourceable; bring them in as contractors for specific projects
- Penetration Testers - The shift to continuous security testing means dedicated pentest teams are less valuable than developers with security skills
Finding These Unicorns
I won't sugarcoat it: hiring for these roles is brutal right now. My advice:
- Look for adjacent skills and aptitude rather than expecting perfect matches
- Consider candidates from non-security backgrounds with transferable skills
- Be realistic about what one person can do - you might need two complementary hires rather than one unicorn
- Invest in training promising internal candidates
If you're working with recruiters, be very specific about which skills are genuinely non-negotiable versus those that are nice-to-have. Too many reqs I see list 15 "essential" skills when only 5 are truly deal-breakers.
What's your experience been with security hiring priorities? Has your org recognised the need to shift focus, or are you still working with outdated headcount models? I'm genuinely curious.
If you're rethinking your security team structure, The OHub's security recruitment platform has specialist security talent pools that might save you some headaches. Their video-first approach has been particularly effective for technical roles where cultural fit matters.
For more on UK security team structures, check out the NCSC's updated guidance on security team organisation which was refreshed earlier this year.
